Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 85553 invoked from network); 7 Nov 2010 17:58:00 -0000 Received: from unknown (HELO mail.apache.org) (140.211.11.3) by 140.211.11.9 with SMTP; 7 Nov 2010 17:58:00 -0000 Received: (qmail 37110 invoked by uid 500); 7 Nov 2010 17:58:29 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 36914 invoked by uid 500); 7 Nov 2010 17:58:28 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 36901 invoked by uid 99); 7 Nov 2010 17:58:28 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 07 Nov 2010 17:58:28 +0000 X-ASF-Spam-Status: No, hits=2.2 required=10.0 tests=FREEMAIL_FROM,HTML_MESSAGE,RCVD_IN_DNSWL_NONE,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: domain of mgainty@hotmail.com designates 65.55.111.80 as permitted sender) Received: from [65.55.111.80] (HELO blu0-omc2-s5.blu0.hotmail.com) (65.55.111.80) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 07 Nov 2010 17:58:20 +0000 Received: from BLU142-W9 ([65.55.111.73]) by blu0-omc2-s5.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675); Sun, 7 Nov 2010 09:57:58 -0800 Message-ID: Content-Type: multipart/alternative; boundary="_7ebc60b2-dada-48ff-b29e-43a301ec0c66_" X-Originating-IP: [71.192.158.205] From: Martin Gainty To: Tomcat Users List Subject: RE: Malicious host is crashing my server Date: Sun, 7 Nov 2010 12:57:58 -0500 Importance: Normal In-Reply-To: <99C8B2929B39C24493377AC7A121E21F99F892D730@USEA-EXCH8.na.uis.unisys.com> References: <745267.95902.qm@web54409.mail.re2.yahoo.com>,<99C8B2929B39C24493377AC7A121E21F99F892D730@USEA-EXCH8.na.uis.unisys.com> MIME-Version: 1.0 X-OriginalArrivalTime: 07 Nov 2010 17:57:58.0543 (UTC) FILETIME=[4FE6F1F0:01CB7EA5] X-Virus-Checked: Checked by ClamAV on apache.org --_7ebc60b2-dada-48ff-b29e-43a301ec0c66_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable the culprit will change IPs are you implementing SSL? are you encrypting your data before putting on the wire? Martin=20 ______________________________________________=20 Verzicht und Vertraulichkeitanmerkung/Note de d=E9ni et de confidentialit= =E9 Diese Nachricht ist vertraulich. Sollten Sie nicht der vorgesehene Empfaeng= er sein=2C so bitten wir hoeflich um eine Mitteilung. Jede unbefugte Weiter= leitung oder Fertigung einer Kopie ist unzulaessig. Diese Nachricht dient l= ediglich dem Austausch von Informationen und entfaltet keine rechtliche Bin= dungswirkung. Aufgrund der leichten Manipulierbarkeit von E-Mails koennen w= ir keine Haftung fuer den Inhalt uebernehmen. Ce message est confidentiel et peut =EAtre privil=E9gi=E9. Si vous n'=EAtes= pas le destinataire pr=E9vu=2C nous te demandons avec bont=E9 que pour sat= isfaire informez l'exp=E9diteur. N'importe quelle diffusion non autoris=E9e= ou la copie de ceci est interdite. Ce message sert =E0 l'information seule= ment et n'aura pas n'importe quel effet l=E9galement obligatoire. =C9tant d= onn=E9 que les email peuvent facilement =EAtre sujets =E0 la manipulation= =2C nous ne pouvons accepter aucune responsabilit=E9 pour le contenu fourni= . =20 > From: Chuck.Caldarale@unisys.com > To: users@tomcat.apache.org > Date: Sun=2C 7 Nov 2010 11:48:20 -0600 > Subject: RE: Malicious host is crashing my server >=20 > > From: Assaf [mailto:assafn@yahoo.com]=20 > > Subject: Malicious host is crashing my server >=20 > > what can I do to better protect? >=20 > As a temporary preventive measure=2C you can disable access from this par= ticular IP address by configuring the RemoteAddrValve in server.xml: >=20 > >=20 > That should give you some time to work out the real fix. >=20 > - Chuck >=20 >=20 > THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY = MATERIAL and is thus for use only by the intended recipient. If you receive= d this in error=2C please contact the sender and delete the e-mail and its = attachments from all computers. >=20 >=20 > --------------------------------------------------------------------- > To unsubscribe=2C e-mail: users-unsubscribe@tomcat.apache.org > For additional commands=2C e-mail: users-help@tomcat.apache.org >=20 = --_7ebc60b2-dada-48ff-b29e-43a301ec0c66_--